Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orftokenendian_convert in exec/totemsrp.c via a large UDP packet. (CVE-2025-30472)
{ "section": "core" }